Poisoning
Attacker's session plants malicious memory. Retrieved on trigger for other user. Cross-tenant risk.
Advertisement
Tenant isolation
Memory partitioned per user/organization. Never shared. Vector DB namespace enforcement.
Advertisement
PII in memory
User shares SSN in one session. Persists. Retrieved in unrelated context. Redact on ingest.
Deletion
User request to delete memory. Full purge, not tombstone. Also purge derived embeddings.